Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise SaaS applications.
Visit Website ↗ + Add to CompareOverview
Obsidian Security provides a SaaS security posture management (SSPM) platform that monitors identity behavior, configuration drift, and third-party app risk across an organization’s SaaS estate (Salesforce, Workday, Microsoft 365, Okta, and similar). The core thesis is that as enterprises shift critical workflows into SaaS applications outside traditional network perimeters, most breaches in that layer trace back to compromised identities, over-permissioned integrations, and misconfigurations rather than classic network intrusion, and existing SIEM/CASB tooling wasn’t built with SaaS-native telemetry in mind.
Founded in 2017 and headquartered in Newport Beach, California, Obsidian has raised roughly $204 million across four rounds, including a $90 million Series C in 2022 led by Menlo Ventures, Norwest Venture Partners, and IVP, and an $85 million Series D that valued the company at approximately $1.1 billion. In 2023 the company extended its platform to unify SaaS security posture monitoring with continuous compliance-monitoring capabilities, aimed at giving security and compliance teams a shared view of SaaS risk.
Obsidian competes in a increasingly crowded SSPM/ITDR field against both dedicated SSPM vendors and SaaS-security modules bundled into larger identity and CASB platforms, but its unicorn-level valuation and sustained, multi-round venture backing from top-tier investors are independently verifiable signals of investor confidence and market traction relative to smaller category entrants.
Innovation Matrix Assessment
Extended its core SSPM platform with continuous compliance-monitoring capabilities in 2023 on top of ongoing identity-threat-detection additions, a steady, well-resourced product cadence funded by sustained venture investment.
As an API-based, agentless SaaS monitoring platform it integrates without requiring endpoint agents or network changes, though deployment depth still depends on how many SaaS apps a customer connects.
An $85M Series D at a reported $1.1B valuation, following a $90M Series C from Menlo Ventures, Norwest, and IVP, is independently reported and represents real, sustained investor momentum relative to most category peers.
SSPM as a category meaningfully addresses a real gap left by legacy CASB/SIEM tools that weren't built for SaaS-native identity telemetry, though Obsidian is one of several well-funded vendors applying a similar approach rather than a singular technical breakthrough.
Independent validation comes primarily through investor due diligence implied by a $1.1B valuation and continued backing from repeat institutional investors; specific breach-prevention or detection-accuracy statistics found in company materials are vendor-sourced and not independently benchmarked here.
SaaS-identity compromise (credential theft, OAuth token abuse, misconfigured integrations) is a well-documented and growing breach vector, keeping SSPM squarely relevant to current enterprise risk priorities.
Why CISOs Should Care
Gives security teams identity-centric visibility and threat detection across the SaaS applications where a large and growing share of business-critical data now lives, closing a blind spot legacy network-centric tools don't cover.
What Makes It Different
Combines SaaS security posture monitoring with continuous compliance monitoring in one platform, aiming to serve both security and compliance teams rather than security alone.
The Matrix Verdict
72/100 — MEANINGFUL INNOVATOR
A well-capitalized, unicorn-valued SSPM leader with real institutional backing and a genuinely relevant identity-centric approach, though it competes in an increasingly crowded field rather than holding a unique technical moat.
Editorial Note: Claims vs. Verified Findings
Funding amounts, lead investors, and the reported $1.1B Series D valuation are independently reported by multiple outlets (VentureBeat, BusinessWire, MSSP Alert); specific product efficacy/detection-accuracy statistics are vendor-sourced marketing claims that were not independently verified here.
Sources
Alternatives to Obsidian Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Tigera
Creator and commercial steward of Project Calico, the most widely adopted Kubernetes networking and network-policy engine, extended into…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…